markstream-vue2-cli
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill focuses on legitimate library configuration and provides appropriate developer guidance for legacy environments.
- [EXTERNAL_DOWNLOADS]: The instructions reference the installation of the 'markstream-vue2' and '@vue/composition-api' packages via standard package managers.
- [EXTERNAL_DOWNLOADS]: The skill mentions optional usage of CDN-hosted workers for KaTeX and Mermaid rendering, providing a security note to review Content Security Policy (CSP) and dependency trust.
- [SAFE]: Indirect Prompt Injection surface: The skill provides a component for rendering user-controlled Markdown content.
- Ingestion points: The 'content' prop in the MarkdownRender component (SKILL.md).
- Boundary markers: The instructions mandate preserving safe rendering defaults and strict configurations for Mermaid.
- Capability inventory: Tool access is limited to the platforms defined in the skill metadata (claude, cursor, gemini, codex).
- Sanitization: Instructions explicitly call for keeping HTML safe and validating the rendering output in the build environment.
Audit Metadata